1. Data controller
The data controller is [Ad Soyad / Ticaret Unvanı] ([T.C. Kimlik No / Vergi Kimlik No]), [Açık adres — mahalle, cadde, no, ilçe/il, posta kodu], Türkiye.
Contact: [email protected]
This notice is also prepared to satisfy the transparency obligation under Article 10 of the Turkish Personal Data Protection Law No. 6698 (“KVKK”). For individuals in the European Economic Area, the Operator also acts as controller within the meaning of the GDPR.
2. Categories of data processed
The following data is processed in connection with the Service:
| Category | Data | Source |
|---|---|---|
| Identity and contact | Email address and, if provided, name | Directly from you, or from Google if you sign in with Google |
| Account security | Irreversible hash of your password (PBKDF2-SHA256), email verification status, password change timestamp, session cookie | Generated by the system |
| Preferences | Interface language, theme, notification settings, tour/onboarding state | From you |
| Workspace content | Brand name and domain, competitor names, monitored questions, brand facts, tags, workspace name | From you |
| Measurement output | Response texts obtained from AI platforms, brand mentions, ranking, tone analysis, cited sources, scores, alerts, recommendations, audit results | Generated by the system |
| Team data | Email addresses and roles of people you invite | From you |
| Subscription data | Plan, subscription status, period end date, subscription identifier at the payment provider | From the payment provider |
| Integration secrets | Slack webhook URL, Telegram bot token and chat identifier that you enter; irreversible hashes of your API keys | From you |
| Visitor traffic (optional) | Via the snippet you add to your site: browser/bot identifier (user-agent), path visited, referrer, source platform and timestamp | From your site’s visitors — IP addresses are NOT collected or stored |
3. Purposes and legal bases
Where we rely on legitimate interests we carry out a balancing assessment, and you have the right to object to that processing.
| Purpose | KVKK Art. 5 basis | GDPR Art. 6 basis |
|---|---|---|
| Creating your account, authenticating you and providing the Service | Necessary for the conclusion or performance of a contract | Performance of a contract (b) |
| Managing subscriptions, billing and plan entitlements | Performance of a contract; legal obligation | Performance of a contract (b); legal obligation (c) |
| Running your questions on AI platforms and analysing the results | Performance of a contract | Performance of a contract (b) |
| Sending alert, report and informational emails | Performance of a contract; legitimate interest | Performance of a contract (b); legitimate interest (f) |
| Preventing abuse, fraud and security incidents (rate limiting, logging) | Legitimate interest | Legitimate interest (f) |
| Operating, debugging and improving the Service | Legitimate interest | Legitimate interest (f) |
| Statutory retention and responding to competent authorities | Legal obligation | Legal obligation (c) |
| Transfers to AI providers located abroad | Explicit consent, or necessity for performance of a contract (see section 5) | Performance of a contract (b) / Art. 49(1)(b) |
4. Data sent to AI platforms
The core function of the Service is to send the questions you define to AI platforms. The content transferred to those platforms consists of: the question texts you define for monitoring; and, during the analysis stage, your brand name, your competitor names, the brand facts you enter, and the response text returned by the platform.
Your account details (email address, name, password, subscription information) are not sent to those platforms.
We strongly recommend that you do not write personal data, trade secrets or confidential information into question texts, as such content is by definition transmitted to third-party platforms.
You can manage which platforms are used from Settings › Platforms within the Service and disable any platform you choose. You may also disable AI-assisted analysis entirely.
5. International transfers
By reason of how the Service operates, certain data is transferred to service providers established outside Türkiye. The recipients, the data transferred and the purposes are set out below:
| Recipient | Country | Data transferred | Purpose |
|---|---|---|---|
| OpenAI | USA | Question texts, brand/competitor names, analysis prompts | Obtaining and analysing ChatGPT responses |
| Anthropic | USA | Question texts, brand/competitor names, response texts | Obtaining Claude responses; analysis engine |
| xAI | USA | Question texts | Obtaining Grok responses |
| USA | Question texts; email and name if you sign in with Google | Obtaining Gemini responses; authentication | |
| DeepSeek | People’s Republic of China | Question texts | Obtaining DeepSeek responses |
| Creem | Ireland / EU | Email address, subscription and payment data | Payment and billing (Merchant of Record) |
| Slack / Telegram (only if you configure it) | USA / other | Alert texts | Notifications through the channel you choose |
6. Retention periods
When you delete your account, your data in the live system is erased immediately. Backups taken before deletion age out of rotation within at most 14 days of your request. Retention obligations arising from law (for example financial records) are reserved.
| Data | Retention |
|---|---|
| Account and profile data | For as long as the account remains open; erased immediately on account deletion |
| Workspace content and measurement output | For as long as the account remains open; erased together with all related records when the account or workspace is deleted |
| History shown in the dashboard | Displayed 7, 30 or 365 days retrospectively depending on your plan (data is not deleted earlier; only the display window is limited) |
| Visitor traffic records | For as long as the account remains open; erased when the workspace is deleted |
| Email verification and password reset codes | Stored as hashes; at most 24 hours and 1 hour respectively |
| Team invitations | 7 days (expire if unused) |
| Payment event records (duplicate protection) | Retained in line with accounting and evidentiary obligations |
| Server logs (error and security records) | Short-lived on the hosting infrastructure; kept free of personal data so far as practicable |
| Backups | Taken as automatically rotated snapshots of the entire server; older snapshots are deleted by the rotation within at most 14 days |
7. Sharing of data
We do not sell or rent your personal data and we do not share it with third parties for advertising purposes.
Data is shared only: (i) with the service providers listed in section 5 that are necessary to provide the Service; (ii) with infrastructure providers such as hosting and email delivery; (iii) with integrations you configure on your own instruction (Slack, Telegram, shared report link); and (iv) in response to duly made requests from competent public authorities.
When you enable the report sharing link, anyone holding that link can view the report without signing in. The link contains only report sections; question texts, responses, settings and account data are not shared. You may regenerate or disable the link at any time.
8. Security measures
The principal technical and organisational measures we apply are:
- Encryption of all traffic with TLS, with HSTS enforced.
- Storage of passwords in irreversible form (PBKDF2-SHA256, 120,000 iterations, random salt); passwords are never held in readable form.
- Session cookies protected with httpOnly, SameSite and, in production, Secure flags; invalidation of all prior sessions on password change.
- Workspace-level data isolation and role-based access (owner / editor / viewer).
- Rate limiting on sign-in, registration and other sensitive endpoints to throttle brute-force attempts.
- Address validation against server-side request forgery (SSRF), blocking access to internal network and cloud metadata addresses.
- Storage of API keys and invitation codes only as irreversible hashes.
- Automated nightly database backups retained for 14 days.
- No advertising or third-party analytics cookies whatsoever.
9. Your rights
Under Article 11 of the KVKK you have the right to apply to the data controller to: learn whether your personal data is processed; request information if it has been processed; learn the purpose of processing and whether it is used in accordance with that purpose; know the third parties to whom data is transferred domestically or abroad; request rectification if data is incomplete or inaccurate; request erasure or destruction; request that rectification, erasure and destruction be notified to third parties to whom data was transferred; object to a result adverse to you arising from analysis solely by automated systems; and claim compensation for loss suffered due to unlawful processing.
If the GDPR applies to you, you additionally have rights of access, rectification, erasure, restriction of processing, data portability and objection; the right to withdraw consent where processing is based on consent; and the right to lodge a complaint with a competent supervisory authority.
You can exercise several of these rights directly within the Service: export your data as CSV, update your account details, and permanently delete your account together with all your data.
Requests may be sent to [email protected] and are concluded within thirty (30) days at the latest. We may request additional information to verify the identity of the applicant.
10. Automated decisions and profiling
The Service does not produce decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Scores, recommendations and priority ratings within the Service are analytical outputs relating to your brand’s visibility and do not constitute an assessment of an individual.
11. Children’s data
The Service is not directed at persons under 18 and we do not knowingly process the personal data of persons under 18. If we learn that such data has been processed, it is deleted without delay.
12. Changes
This policy may be updated in line with the development of the Service and with legislation. Material changes are notified by email and/or within the Service before they take effect.
Effective date: August 6, 2026 · Last updated: August 6, 2026